Security Advisory
CVE-2025-4086
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
A specially crafted filename containing a large number of encoded newline characters could obscure the files extension when displayed in the download dialog. *This bug only affects Thunderbird for Android. Other versions of Thunderbird are unaffected.*. This vulnerability was fixed in Firefox 138 and Thunderbird 138.